peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

398,672 CVEs 1,728 on KEV 17,267 EPSS ≥ 10% 25,086 with exploits synced 2026-09-28

169,085 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2010-3886 EXP The CTimeoutEventList::InsertIntoTimeoutList function in Microsoft mshtml.dll uses a certain pointer value as part of producing Timer ID values for th… Patch early 4.3 medium 16.5% 2010-10-08
CVE-2003-0009 EXP Cross-site scripting (XSS) vulnerability in Help and Support Center for Microsoft Windows Me allows remote attackers to execute arbitrary script in th… Patch early 6.8 medium 16.5% 2003-03-07
CVE-2006-2661 EXP ftutil.c in Freetype before 2.2 allows remote attackers to cause a denial of service (crash) via a crafted font file that triggers a null dereference. Patch early 5.0 medium 16.5% 2006-05-30
CVE-2006-4889 EXP Multiple PHP remote file inclusion vulnerabilities in Telekorn SignKorn Guestbook (SL) 1.3 and earlier, when register_globals is enabled, allow remote… Patch early 5.1 medium 16.4% 2006-09-19
CVE-2021-25161 EXP A remote cross-site scripting (xss) vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.4.x:… Patch early 6.1 medium 16.4% 2021-03-30
CVE-2007-4890 EXP Absolute directory traversal vulnerability in a certain ActiveX control in the VB To VSI Support Library (VBTOVSI.DLL) 1.0.0.0 in Microsoft Visual Stu… Patch early 5.8 medium 16.4% 2007-09-14
CVE-2010-1532 EXP Directory traversal vulnerability in the givesight PowerMail Pro (com_powermail) component 1.5.3 for Joomla! allows remote attackers to read arbitrary… Patch early 5.0 medium 16.3% 2010-04-26
CVE-2009-1217 EXP Off-by-one error in the GpFont::SetData function in gdiplus.dll in Microsoft GDI+ on Windows XP allows remote attackers to cause a denial of service (… Patch early 4.3 medium 16.3% 2009-04-01
CVE-2005-4717 EXP Microsoft Internet Explorer 6.0 on Windows NT 4.0 SP6a, Windows 2000 SP4, Windows XP SP1, Windows XP SP2, and Windows Server 2003 SP1 allows remote at… Patch early 5.0 medium 16.3% 2005-12-31
CVE-2015-5065 EXP Absolute path traversal vulnerability in proxy.php in the google currency lookup in the Paypal Currency Converter Basic For WooCommerce plugin before… Patch early 5.0 medium 16.3% 2015-06-24
CVE-2000-0580 EXP Windows 2000 Server allows remote attackers to cause a denial of service by sending a continuous stream of binary zeros to various TCP and UDP ports,… Patch early 5.0 medium 16.3% 2000-06-30
CVE-2008-2005 EXP The SuiteLink Service (aka slssvc.exe) in WonderWare SuiteLink before 2.0 Patch 01, as used in WonderWare InTouch 8.0, allows remote attackers to caus… Patch early 5.0 medium 16.3% 2008-05-06
CVE-2013-3166 EXP Cross-site scripting (XSS) vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to inject arbitrary web script or HTML vi… Patch early 4.3 medium 16.3% 2013-07-10
CVE-2007-2718 EXP Cross-site scripting (XSS) vulnerability in the WebMail system in Stalker CommuniGate Pro 5.1.8 and earlier, when using Microsoft Internet Explorer, a… Patch early 4.3 medium 16.3% 2007-05-16
CVE-2006-0911 EXP NmService.exe in Ipswitch WhatsUp Professional 2006 allows remote attackers to cause a denial of service (CPU consumption) via crafted requests to Log… Patch early 5.0 medium 16.3% 2006-02-28
CVE-2009-4019 EXP mysqld in MySQL 5.0.x before 5.0.88 and 5.1.x before 5.1.41 does not (1) properly handle errors during execution of certain SELECT statements with sub… Patch early 4.0 medium 16.3% 2009-11-30
CVE-2015-4666 EXP Directory traversal vulnerability in opm/read_sessionlog.php in Xceedium Xsuite 2.4.4.5 and earlier allows remote attackers to read arbitrary files vi… Patch early 5.0 medium 16.2% 2015-08-13
CVE-2004-0474 EXP Help Center (HelpCtr.exe) may allow remote attackers to read or execute arbitrary files via an "http://" or "file://" argument to the topic parameter… Patch early 5.1 medium 16.2% 2004-07-07
CVE-2000-1058 EXP Buffer overflow in OverView5 CGI program in HP OpenView Network Node Manager (NNM) 6.1 and earlier allows remote attackers to cause a denial of servic… Patch early 5.0 medium 16.2% 2000-12-11
CVE-2017-10355 EXP Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Networking). Supported versions that are affected a… Patch early 5.3 medium 16.2% 2017-10-19
CVE-2006-4384 EXP Heap-based buffer overflow in Apple QuickTime before 7.1.3 allows user-assisted remote attackers to execute arbitrary code via the COLOR_64 chunk in a… Patch early 5.1 medium 16.2% 2006-09-12
CVE-2018-11412 EXP In the Linux kernel 4.13 through 4.16.11, ext4_read_inline_data() in fs/ext4/inline.c performs a memcpy with an untrusted length value in certain circ… Patch early 5.9 medium 16.2% 2018-05-24
CVE-2013-1603 EXP An Authentication vulnerability exists in D-LINK WCS-1100 1.02, TESCO DCS-2121 1.05_TESCO, TESCO DCS-2102 1.05_TESCO, DCS-7510 1.00, DCS-7410 1.00, DC… Patch early 5.3 medium 16.1% 2020-01-28
CVE-2009-1872 EXP Multiple cross-site scripting (XSS) vulnerabilities in Adobe ColdFusion Server 8.0.1, 8, and earlier allow remote attackers to inject arbitrary web sc… Patch early 4.3 medium 16.1% 2009-08-18
CVE-2021-24276 EXP The Contact Form by Supsystic WordPress plugin before 1.7.15 did not sanitise the tab parameter of its options page before outputting it in an attribu… Patch early 6.1 medium 16% 2021-05-05
CVE-2017-14016 EXP A Stack-based Buffer Overflow issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. The application lacks proper validation of… Patch early 6.3 medium 16% 2017-11-06
CVE-2004-2090 EXP Microsoft Internet Explorer 5.0.1 through 6.0 allows remote attackers to determine the existence of arbitrary files via the VBScript LoadPicture metho… Patch early 5.0 medium 16% 2004-02-07
CVE-2010-1658 EXP Directory traversal vulnerability in the Code-Garage NoticeBoard (com_noticeboard) component 1.3 for Joomla! allows remote attackers to read arbitrary… Patch early 5.0 medium 16% 2010-05-03
CVE-2020-28351 EXP The conferencing component on Mitel ShoreTel 19.46.1802.0 devices could allow an unauthenticated attacker to conduct a reflected cross-site scripting… Patch early 6.1 medium 16% 2020-11-09
CVE-2024-8945 EXP A vulnerability has been found in CodeCanyon RISE Ultimate Project Manager 3.7.0 and classified as critical. This vulnerability affects unknown code o… Patch early 5.5 medium 16% 2024-09-17
← previous page 41 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt